kMastaFlash wrote: » Honestly, I haven't seen this in my GCIH books. Which edition of the manuals are you using? If you want to learn about ShellShock, just reference your CEH manuals. If you took CEHv9, it should be covered in there.
xxxkaliboyxxx wrote: » Just google it and read up on it. I think I got a question on Shellshock in the actual test.
BillHoo wrote: » According to the index of my books current from 2016. It was in Volume 4 (don't have the book handy, just my index), Pages 88 and 89. I think it was in a section regarding Applications or Web Applications Security, right after OWASP by a few pages.
BillHoo wrote: » I always reiterate the value of getting the SANS course to take the exam vs. challenging the exam. I think shellshock is a good example. Search the internet and you might be able to find pages of information, or even enough to write a small booklet or article on the subject. But when it comes to the exam, the test question would want to know a specific aspect of shellshock as explained in the book/class. Many times this is going to be maybe one sentence verbatim, or a defining concept. What is shellshock? It's a command injection where your use commands to trick the web server into taking commands. Pick the answer that's closest to the description.